Unconditionally secure quantum key-distribution with relatively strong signal pulse 
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We propose an unconditionally secure quantum key distribution (QKD) protocol, which uses a 
relatively strong signal pulse. While our protocol shares similar security bases as the Bennett 1992 
protocol with a strong reference pulse (B92), our scheme uses a smaller number of detectors and 
it is robust against Rayleigh scattering in an optical fibre. We derive a lower bound of secret key 
generation rate of our protocol and show that our protocol can cover relatively long distances, 
assuming precise phase modulations and stable interferometers. 
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Quantum key distribution (QKD) provides a way to 
share a secret key with arbitrary small leakage of its infor- 
mation to an unauthorized party (Eve). The first QKD 
protocol, BB84, was proposed in [l!], and it originally as- 
sumes the use of a single-photon source. In it was 
found that even if we use attenuated laser light, we can 
still cover long distances with the help of the decoy state 
method. In this method, the sender (Alice) emits a sig- 
nal pulse (SP) together with extra pulses (decoy states) 
whose properties are the same as those of the SP except 
for their intensities. With the decoy states, Alice and the 
receiver (Bob) can monitor Eve's action tightly so that 
they can achieve long distances. One of the drawbacks 
of this method is the increase of the number of classical 
communications needed, and it has been reported that 
the fluctuations of intensities of decoy states decrease the 
achievable distance significantly Q. This means that a 
simpler protocol without decoy states might be preferable 
in some scenario. 

The Bennett 1992 protocol with a strong reference 
pulse (B92) Q uses another approach to cover long dis- 
tances. In B92, a dim SP is sent together with strong 
reference pulse (SRP), and the unconditional security 
of this protocol was proven in 0, Assuming typi- 
cal experimental parameters without taking into account 
Rayleigh scattering in an optical fibre, in Q it is con- 
cluded that if the intensity of SP is about 0.1 and the 
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FIG. 1: The essential experimental setup for B92. PM: phase 
modulator. 



one for SRP is more than 10^'^, then long distances can 
be achieved. However, this strong intensity of the ref- 
erence light highly causes Rayleigh scattering, and as a 
result, the achievable distance of practical B92 is very 
limited due to the bit errors induced by the scattering. 

In this paper, we propose an unconditionally secure 
QKD protocol without decoy states, which shares simi- 
lar security bases as the B92 and uses the same intensities 
both for the SP and reference pulse (RP). The intensity 
can be set to be much weaker than the one for the SRP 
in the B92. Thus, it is expected that our protocol is free 
from the Rayleigh scattering problem. A complete secu- 
rity proof for our protocol in terms of achievable distances 
is still missing. However, we show that even with an 
unconditional security proof that does not fully capture 
the security bases, our protocol still can cover relatively 
long distances assuming precise and stable phase modu- 
lations. We expect therefore that our protocol keeps the 
door open for expanding the achievable distances. Thus, 
our protocol is not only interesting from a practical point 
of view, but also it poses an interesting theoretical prob- 
lem. Note that a similar protocol with strong signal light, 
homodyne detection, and threshold values has been pro- 
posed by Inoue and Hayashi 7J • 

In this paper, we first explain how the B92 works to 
illustrate its security essence, and then we introduce a 
new protocol. Next, we prove unconditional security of 
the new protocol with additional assumptions on Bob's 
detectors, and we show some examples of its key genera- 
tion rate in terms of distances. 

In the experiment for the B92, we use double Mach- 
Zehnder interferometers, however, the essence can be ex- 
plained by just a single Mach-Zehnder interferometer (see 
Fig. [T]) . In this protocol, Alice prepares a coherent light 
pulse in a state |(— 1)^'*\/k)sp|\/m)srp depending on a 
random bit value Ja = 0, 1, where n and /i represent re- 
spectively the mean photon number of the SP and the 
SRP. On the receiving side. Bob uses an asymmetric 
beam splitter BSl with reflectivity n/fx, which splits the 
reference pulse into a weak pulse and a strong one. The 
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FIG. 2; The essential experimental setup for our new proto- 
col. 



intensity of the weak pulse is equalized to that of the 
incoming signal pulse so that we have an interference in 
the symmetric beam splitter BS2, i.e., if a "signal reading 
detector" Dq (Di) clicks, then Bob can infer that Alice 
has set — [ja = !)• Note that since the incoming SP 
is very weak, in most cases Bob has no click at the signal 
reading detectors, which we call inconclusive events. In 
addition to using the signal reading detectors, Bob needs 
to test whether the reference pulse always arrives by us- 
ing a "monitoring detector" Dm just after the BSl. After 
these measurements are performed. Bob needs to tell Al- 
ice whether he has obtained a conclusive result and the 
monitoring detector has clicked or not. 

The essence of the security of the B92 can be captured 
by considering the following two specific attacks. The 
first one is so-called beam-splitting attack [s^ where Eve 
uses beam splitters to split some portions of both the 
signal and the reference pulse to her side. In the B92 
the overlap of the two signal states sent by Alice is very 
large, which means that the probability that both of Eve 
and Bob have the conclusive results is very small. As a 
result, Eve's knowledge on Bob's bit values is strongly 
limited so that a beam-splitting attack is not critical in 
the B92. 

The second strategy for Eve is an unambiguous state 
discrimination (USD) attack where she performs an 
USD measurement on each signal states sent by Alice. 
USD succeeds with small probability, and when it dose. 
Eve can obtain full information on the bit value without 
introducing any bit error. If it fails, Eve may send a 
vacuum as a fake signal to Bob, which disguises for signal 
loss events. If this vacuum induces no bit errors, which 
is the case for the single-photon B92 (S-B92) [9|, then 
the achievable distances for the B92 is highly limited. 
Note, however, that Eve needs also to send the SRP in 
the B92 since Bob tests the its presence with Dm. Thus, 
sending the vacuum as the fake signal results in a random 
click because of the SRP, which reveals Eve's existence. 
In other words, the monitoring detector keeps Eve from 
performing the USD attack. 

We call the first basis of the security of the B92 as high 
nonorthogonality and the second one as high monitoring 
ability. In what follows, we show that these bases can 



be accomplished by a simple new protocol. Fig. [5] is a 
schematic of an experimental setup for our new protocol. 
Here, Bob's interferometer is set up in such a way that 
if the two incoming pulses have the same phase, then a 
"signal reading detector" Ds always has a vacuum state. 

Next, we describe steps of our new protocol. 
(SI) Ahce prepares coherent lights pulse in a state 
|gi(~i)^^5^y^^gp|^^^j^p according to the random bit 
value Ja, and sends these pulses to Bob. Here, 5 is a 
small positive number. (S2) Bob randomly chooses his 
bit value js and performs a phase modulation of e*^^^^^^ ^ 
to the incoming signal pulse. (S3) Bob records whether 
the monitoring detector Dm clicks and whether the signal 
reading detector Ds clicks. (S4) Bob tells Alice whether 
he has obtained a conclusive event, i.e., Ds clicks or not. 
(S5) If Bob has obtained the conclusive event, Alice keeps 
the corresponding bit value Ja- Otherwise, she discards 
it. (S6) Alice and Bob repeat (S1)-(S5) many times. (S7) 
If the ratio of the click events of Dm is low, then they 
abort the protocol. (S8) Alice and Bob estimate the bit 
error rate from test bits. Then, they perform classical bit 
error correction (CEC) and classical privacy ampli- 
fication (CPA) based on the estimated bit error rate 
and other available observables, such as the ratio of click 
events by Dm and Ds so that they share a secret key. 

Based on the same reason in the B92, this protocol 
is supposed to be strong against beam-splitting attack 
and USD attack assuming relatively large fj, and small 
enough S. It is not difficult to see in noise-free cases that 
Alice and Bob share a bit value jA — js with probability 
1 — e"^'"'"™ ^, where 77 is a single-photon transmission 
rate of the channel together with the efficiency of a detec- 
tor. One can also see that the monitoring detector clicks 
with probability of 1 — e"^'"'™'' Thus, in order for our 
protocol to meet high monitoring ability, 1 — Q-'^'ntJ-cos s 
has to be close to 1. On the other hand, high nonorthogo- 
nality requires that the inner product of Alice's two input 
state is large, i.e., e"''''"™ ^ ~ 1. Combining them to- 
gether, we conclude that as long as we set 11 > l/rj and 
S < our protocol should be secure based on the same 
bases as the B92. It follows that when the communica- 
tion distance / is about 100 (km), we should set /z > IC* 
and S < 10~^ according to experimental parameters 
77 — 0.045 * 10~^T^ . This means that our protocol is 
more robust against Rayleigh scattering than the B92 
where we use more than 10^'^ mean photon number for 
the SRP. Thus, we expect that our protocol can cover 
long distances even in practice. 

Although we miss a security proof that fully incorpo- 
rates the high monitoring ability in our new protocol, we 
can still prove the unconditional security of our proto- 
col by directly applying the security proof of the S-B92 
[9|]. For the proof, we additionally assume that Bob's 
detector can discriminate among vacuum, single-photon, 
and multi-photon, which is helpful to define Bob's qubit 
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space as we will see later. We accordingly re-define 
the conclusive (inconclusive) event as the case where Ds 
(Dm) detects a single-photon and Dm (Ds) has a vac- 
uum, and we define all the other events as losses that 
will be discarded. Following these changes, the modi- 
fied version of our protocol works in the same manner 
as the original one. Throughout the proof, we also as- 
sume that all imperfections in Alice's and Bob's devices 
are under Eve's control. For the later convenience, we 
define |0)sp|s)rp = |0^) and |s)sp|0)rp = jl^) as a 
basis (Z-basis) of a qubit state, where \s) is a single- 
photon state, and we also define X-basis eigenstate and 
Y-basis eigenstate as = + {^^Yl^z)) ^^'^ 

\jy) = 75(10.) +z(-1)-'|1.)), respectively. 

In order to prove the security of our protocol 
with the additional assumption on Bob's detectors, 
we convert our protocol into an Entanglement Dis- 
tillation Protocol (EDP) [13] ■ First, we consider 
Alice who prepares two qubit in a state |$) = 
7f (|0y)A|e*'^^)sp + |ly)A|e~"'7/I)sp)lVM)RP, sends out 
the system RP and SP to Bob, and performs Y-basis 
measurement on the system A. As a result of this, Al- 
ice sends |e**^)sp|VA')RP and |e""'^)sp|^)Rp ran- 
domly, which is equivalent to Alice in the actual protocol. 
This ends the conversion of Alice's side. 

As for Bob's part, first note that Bob uses a phase 
modulator, linear optics, and photon counters. Thus, 
without changing any measurement outcome, we can as- 
sume that Bob's measurement is preceded by a mea- 
surement Q that measures the total photon number of 
the incoming signal and reference pulses. Note that 
Bob has an access to the measurement outcome of Q 
thanks to the additional assumption on his detectors. 
One can see that Bob's measurement in the subspace 
containing a single-photon is represented by POVM [vi\ 
{Fo,Fi,Finconc}, whcrc Fo = (l/2)P(|(^i)) (P(|^)) = 
|V)(V'I), ^^1 = (l/2)F(|^o»: and Fi„eonc = 1 - Fq - Fi. 
Here, Fq and Fi correspond to the conclusive event, we 
define \ipj) = cos{6/2)\0^) -i{-iy sm{5/2)\L^), and |^) 
is a qubit state orthogonal to \ipj)- 

A crucial point in the conversion to EDP on Bob's 
side is that the measurement on a qubit (a single-photon 
state) can equivalently be executed by applying a filter- 
ing operation [isj whose successful operation is repre- 
sented by a Kraus operator [ll[ Fg — sin{S/2)P{\0x)) + 
cos{S/2)P{\lx)), and then performing Y-basis measure- 
ment. This equivalence can be seen by noticing that 
F, = P{F^\jy)) and Fjnconc = 1 - F^F^. Note that 
the successful filtering operation corresponds to the con- 
clusive evens. It is not difficult to check in noise and 
loss free cases that if Bob's filter succeeds, then Al- 
ice and Bob share a maximally entangled state (MES) 
-^{\0y) A\Oy) B + |ly)A|ly)B)- Thus, bit valucs extracted 
by Y-basis measurement on MES by Alice and Bob are 
identical and secure since MES is a pure state. 



Note that since Bob's measurement is an USD mea- 
surement, our measurement is identical to the one in 
the S-B92 where nonorthogonal single-photon polariza- 
tion states are unambiguously discriminated. Actually, 
POVM in the S-B92 can be immediately obtained by 
changing sin((5/2) a and cos(^/2) \J\ — cP- where a 
characterizes the nonorthogonality of two single-photon 
polarization states Moreover, mathematical expres- 
sions of Alice's nonorthogonal states in our protocol and 
those in the S-B92 are the same. Thus, there is one-to- 
one correspondence between our protocol and the S-B92. 

In the presence of Eve's intervention, Alice and Bob 
do not share a MES even if Bob's filter succeeds. A basic 
idea for proving the security under Eve's intervention is 
to consider the distillation of a MES from a mixed state. 
In Shor and Preskill showed that if Alice and Bob 
can estimate the number of bit errors (nAbit) and phase 
errors (nAph) on nAfii qubit pairs that have passed the 
filter, then they can distill at least nAfii[l — ft,(Abit/Afii) — 
/i(Aph/Afii)] {n 00) of MES. Here, h{x) = -x logj x - 
(1 — x)log2(l — x), and the bit (phase) error represents 
the case where Alice's and Bob's measurement outcomes 
differ in Y (X)-basis. Moreover, according to Shor and 
Preskill's argument, our protocol followed by the EDP 
and Y-basis measurement is equivalent to our protocol 
followed by CEC and CPA. Since the bit error rate can 
be estimated by test bits, if we can estimate the phase 
error rate, then the security proof ends. 

In Q , it is shown that we can estimate the upper bound 
of the phase error rate for the S-B92 since the filtering 
operation relates the phase errors with other observables 
such as bit errors and conclusive events. Thanks to the 
one-to-one correspondence between our protocol and the 
S-B92, we are allowed to directly apply this phase error 
estimation to our protocol so that we obtain the upper 
bound of phase error rate Aph by solving the following 
inequality 

Am - 2Abit < sin(,5).9(C7z) , (1) 

where g{{a, b, c, d)'^) = \foh + \fcd. In this inequality, 
z = (As, Aij;-pi(l- As), Afii, Aph)^, where A^ is fraction 
that Bob obtains the qubit state, Ai^; is a probability of 
Alice having 1 in her Gedanken X-basis measurement, 
Pi takes values inside [0, 1], which must be optimized in 
such a way that it maximizes Aph- Finally, C is a matrix 
whose inverse is expressed as 

/I 1 1 1 \ 

i_ 1 1 

sin2(5/2) cos2(,5/2) sin2(,5/2) cos2(5/2) ' 
\ cos2(5/2) sin2(5/2) / 

/2) 

To illustrate the key generation rate, we consider 
a channel that maps -P(|e''^*''Y^)sp|v^)Rp) i^ito (1 ~ 
p)P(|e±^«^)sp|Vw)Rp) +P^'(|s)sp|0)rp), where < 
p < 1- The first part represents losses in a quantum 
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FIG. 3: (I) The key generation rates. If Rayleigh scattering 
is taken into account, the achievable distances of the B92 
(B92 (1) and B92 (2)) significantly decrease. (II) The optimal 
intensity of the light for the modified version of our protocol. 



channel, and the second part models dark counts in Bob's 
detector since it causes a random click. According to the 
experiment in [l^, p = 1.7x 10^*^ and i] — 0.045 *10^^tS'^ 
neglecting alignment errors. Thus, we have ps — — 
p)27y/ie-2w + Afii (1 - sin^((5)e-2w + p/2, and 

Abit = p/4. 

In Fig. [3] (I), wc plot the key generation rate G — 
Afii(l — /i(Abit/Afii) — ft.(Aph/Afii)) as a function of the 
distance (km) between Alice and Bob. In solid lines (a) 
and (b), we respectively set the precision of the phase 
modulator as A = 25 = 7r/50 and A = 7r/150, and we 
also plot an optimal /i to maximize G in Fig. [3] (II). It is 
seen that the achievable distance for (a) is Z = 66 (km) 
and the one for (b) is Z = 87 (km) , either of which is larger 
than the one for BB84 based on the GLLP formula [IJI 
(dotted line, I = 51). We have confirmed that 87 (km) is 
the maximum distances among examples we have tried. 

For comparisons, we also plot in Fig. [3] (I) the key rate 
for BB84 with infinite number of decoy states [5| (dot- 
ted line, I — 163), and that for the B92 (dashed line). 
For the B92, we define a parameter set (/i,K, a), where 
Vi = rj^ — a^/ffjl, and Vf = rjfi + ay/rjjl express the photon 
number regime — 1] that the monitoring detector 

Dm has to discriminate from the other regime . We fix 
K = l0""-92 and a = 3.2, and we set ^l = 10^ for the B92 
(1) {I = 55) and fi = lO^-^^ for the B92 (2) (/ = 100). 
Thus, in the B92 the photon number detected by Dm has 
a crucial role in the achievable distances. We have con- 
firmed in our protocol (in lines (a) and (b)) that Bob's 
Dm fails to click, i.e., fails to detect a single-photon, 
at least more than 64% of the instances, which are re- 
garded as the losses, while the loss events in the B92 



{Dm fails to detect photons inside the photon number 
regime [I'i,^'/ — 1]) are negligible It follows that our 
security proof fails to make use of the high monitoring 
ability, and we expect that the achievable distances can 
be expanded by using a better security proof that fully 
captures this property. Note that if one takes into ac- 
count Rayleigh scattering, the achievable distances for 
the B92 significantly decreases. Moreover, the use of a 
single signal state might be an advantage of our protocol 
over the decoy state method whose fluctuations make the 
achievable distance short f3\ . 

In summary, we proposed a QKD protocol that shares 
similar security bases as the B92 and might be robust 
against the Rayleigh scattering. We have shown that 
even with an unconditional security proof that does not 
fully capture the security bases, our protocol still can 
cover relatively long distances assuming precise phase 
modulations and stable interferometer. We leave a se- 
curity proof that fully captures the security bases of our 
protocol for the future works. 
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